PT-2010-1174 · Microsoft · Office Powerpoint

Alin Rad Pop

·

Publicado

2010-11-09

·

Atualizado

2025-03-26

·

CVE-2010-2572

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft PowerPoint versions 2002 SP3 through 2003 SP3
Description The issue is a buffer overflow in Microsoft PowerPoint, allowing remote attackers to execute arbitrary code via a crafted PowerPoint 95 document. This can give an attacker full control over the system, enabling them to install programs, view, modify, and delete data, as well as create new accounts with full user rights.
Recommendations For Microsoft PowerPoint versions 2002 SP3 and 2003 SP3, consider disabling the handling of PowerPoint 95 documents until a patch is available. As a temporary workaround, restrict access to the vulnerable component that handles PowerPoint 95 files to minimize the risk of exploitation. Avoid using the vulnerable version of Microsoft PowerPoint to open specially crafted PowerPoint 95 documents until the issue is resolved.

Correção

RCE

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2022-03588
CVE-2010-2572

Produtos afetados

Office Powerpoint